- 11g (8)
- Allgemein (25)
- checkpwd (4)
- CPUApril2009 (2)
- CPUJan2009 (3)
- CPUJul2009 (2)
- CPUOct2009 (3)
- David Litchfield (7)
- Exploit (19)
- Forensics (4)
- Oracle Security (76)
- passwords (7)
- SAP (1)
- Security (16)
- Sentrigo (5)
- software (7)
- source code audit (3)
- SQL Injection (20)
- Tools (18)
- Trainings (2)
- Tutorial (2)
- 5 Feb 2010: Oracle Blackhat video removed from Website
- 4 Feb 2010: Oracle 11g 0day exploit published
- 30 Jan 2010: Selling stolen bank data to the government for 2.5 Million EUR?
- 6 Dez 2009: Dennis Yurichev wrote an article about his FPGA Oracle password cracker
- 29 Nov 2009: IGHASHGPU - Cracking Oracle Passwords with 790 Million Passwords/second
- 25 Nov 2009: How Oracle controls access to security vulnerabilities
- 17 Nov 2009: Metasploit 3.3 is out
- 17 Nov 2009: Security Workshop "Database Activity Monitoring Systems" in London
- 13 Nov 2009: New russian Oracle exploit tool "Oracle Security Tools" (updated)
- 8 Nov 2009: Oracle Database Vault is now certified with SAP
Oracle Security
Other Blogs
SQL Injection
Trainings
- Februar 2010
- Januar 2010
- Dezember 2009
- November 2009
- Oktober 2009
- September 2009
- August 2009
- Juli 2009
- Mai 2009
- April 2009
- März 2009
- Februar 2009
- Januar 2009
- Dezember 2008
- November 2008
- Oktober 2008
- August 2008
- Juli 2008
- Mai 2008
- April 2008
- März 2008
- Februar 2008
- Januar 2008
- Dezember 2007
- November 2007
- Oktober 2007
- September 2007
- August 2007
- Juli 2007
- Juni 2007
- Mai 2007
Oracle, white spaces and unexpected behaviour
Last week I saw the blog entry “select 1.x from t1” from Laurent concerning white spaces in select statements and Tom Kyte’s answer with a short explanation. Tanel Poder wrote a blog entry “Can you write a working SQL statement without using any whitespace?” too.
In my opinion and from the security perspective making whitespaces optional in SQL statements is a bad idea because it’s an unexpected behavior. And this is always a bad idea.
Here a real life example from Oracle itself:
Two years ago I found a SQL Injection Vulnerability in the web component of XMLDB.
The exploit was looking like:
http://url/xmldb?param1=’||(select sysdate from dual)||’
The result was a HTTP page containing the current date in an Oracle error message, a common exploit technique used by attackers.
The bugfix from the Oracle developer responsible for this component was to filter the URL for white spaces. Whenever a whitespace was part of the URL, the query was rejected. That’s why it was still possible to use functions (e.g. SYS_CONTEXT, …) but select statements were refused.
At that time I was not aware that SQL statements can be constructed without white spaces.
But with the knowledge from Laurent’s and Tanel’s blog entries I could rewrite the exploit
http://url/xmldb?param1=’||(select/**/sysdate/**/from”DUAL”)||’
A quick check in the Oracle PL/SQL code shows that some Oracle packages are using whitespaces as token separator (with the function instr()). I was also able to create a buffer overflow with alter session (11g) in SQL*Plus using this technique. I will digg deeper…
Quick question to my readers: Is this just an Oracle behavior or also possible in other databases like SQLServer or DB2.
3 Antworten auf “Oracle, white spaces and unexpected behaviour”
Antwort schreiben
Sie müssen als angemeldet sein, um einen Kommentar schreiben zu können.

15 Jan 2008 bei 13:25
mysql> select/**/current_user;
+—————-+
| current_user |
+—————-+
| root@localhost |
+—————-+
1 row in set (0.00 sec)
Best regards
Maxim
15 Jan 2008 bei 21:25
From SQl Server 2005 SQLCMD
1> select/*a*/count(*)/*b*/from/*c*/information_schema.tables
2> go
———–
559
(1 rows affected)
1> select top 3 1.x from information_schema.tables
2> go
x
—
1
1
1
(3 rows affected)
1>
15 Jan 2008 bei 21:27
Maxim and Gary,
thank you for the update.
Regards
Alex